President Donald Trump signed a memorandum allowing U.S. agencies to conduct hacking operations against transnational crime organizations overseas.
President Donald Trump has issued a National Security Presidential Memorandum that allows US federal law enforcement to execute offensive cyber operations against transnational criminal organizations operating overseas. Essentially, Washington is formally permitting itself to hack the hackers, and this carries significant implications.
The memorandum targets foreign criminal entities that negatively affect Americans through ransomware, phishing, financial fraud, sextortion, and a surge of AI-driven impersonation scams witnessed over the past year. The goal is to disrupt these operations at their origin rather than waiting for the repercussions to impact the US.
The statistics related to this order are quite alarming. The White House reports that cybercrime losses are projected to reach $20.8 billion in 2025, with 73% of US adults having faced online scams. Even more concerning, one in seven young individuals victimized by sextortion has admitted to self-harm, highlighting that the human toll of these networks cannot be quantified solely in financial terms.
The program is structured with proper oversight. A new National Coordination Center, which will function under a Homeland Security Task Force and be jointly led by the Department of Justice and the Department of Homeland Security, will manage operations. The Homeland Security Council is responsible for establishing protocols, and the memorandum requires “rigorous procedures” for review and adherence to the Constitution, US laws, and international treaties.
A particularly notable aspect involves the private sector. The coordination center is instructed to “leverage the capability and innovation of the private sector” to conduct operations under government supervision and control. This means that private companies could potentially be involved in breaking into criminal networks abroad, a threshold many governments have historically been cautious about crossing.
This raises concern for European audiences. State-sanctioned offensive hacking, even against clearly harmful targets, is a capability that could be hard to turn off once activated. A major concern is escalation; criminal groups frequently share infrastructure with legitimate businesses, and attacking one may inadvertently impact the other.
Attribution presents another challenge. Cyber operations are notoriously difficult to track, which is part of what makes them appealing to criminals; that same uncertainty applies when a government conducts operations. A failed attempt or an operation targeting the wrong server in an unintended country may not be easily reversed or convincingly denied.
There’s also the issue of collateral damage. Those managing these criminal enterprises are adept at concealing themselves among regular users. Thus, an operation targeting a scam network or ransomware group risks unintentionally affecting innocent bystanders, foreign companies, or even allied infrastructure, as evidenced by various botnet takedown attempts.
The involvement of private contractors complicates matters further. Giving offensive tools to commercial firms, despite the memo's assurances of “direction and control,” blurs the distinction between public accountability and private interest. Europe has spent considerable time attempting to regulate the commercial spyware industry for this reason, and Washington’s decision to involve contractors in government cyber offensives is likely to attract scrutiny in Brussels.
Admittedly, the threat is genuine, and the current measures are evidently ineffective. Ransomware gangs and scam networks have prospered due to the disparity between their operational locations and their victims’ homes, with traditional law enforcement, constrained by borders, struggling against deepfake-driven fraud and the fraud economy.
The critical question is whether safeguards can be maintained. While “rigorous procedures” and constitutional compliance sound comforting in a fact sheet, the real test will arise the first time an operation fails, when a contractor exceeds their bounds, or when an allied government queries who authorized the code running on a server within its jurisdiction.
Other articles
President Donald Trump signed a memorandum allowing U.S. agencies to conduct hacking operations against transnational crime organizations overseas.
A recent presidential memorandum permits US law enforcement to conduct offensive cyber operations targeting foreign criminal organizations, as well as to engage private contractors for assistance.
